Re: debsums for maintainer scripts

On Thu, 04 Dec 2003 17:36:16 +0100, Thomas Viehmann <tv@beamnet.de> said: 

> Manoj Srivastava wrote:
>> Before we make such a push, we should at least ensure that it is
>> something we really want to do. I think locally generated checksums
>> are a better solution.
> To me, the main use of md5sums seems to be verifying nothing bad (as
> in accident, not malicious manipulation) happened to the extracted
> files.  md5sums included in the packages do that even earlier than
> those generated.

	Earlier than what?  You already can check the integrity of the
 .deb you are installing; don't install corrupted .debs. Now
 admittedly there is a window where files can be corrupted between
 unpacking and creating the checksums, in which case just run the ar
 .. tar -d incantation posted earlier to check the on disk file
 _after_ generating the checksum to make sure that that little window
 is also closed.

